cbcvebase.
CVE-2016-0349
published 2016-06-30

CVE-2016-0349: IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and…

medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmbusiness_process_manager
ibmbusiness_process_manager